Quick reference

Password Best Practices — One Page

Post it by the desk: the current, sane guidance on passwords and multi-factor authentication.

Intended audience
Every employee
Difficulty
Beginner
Estimated time
4 minutes
Access
Free
NIST SP 800-63
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Explain why length and uniqueness matter more than complexity for password strength.
  • Choose an appropriate multi-factor authentication method, preferring an authenticator app or hardware key over SMS.
  • Recognize and avoid common password mistakes such as reuse, sharing, and approving unexpected MFA prompts.

Do

  • Use a password manager and let it generate long, unique passwords.
  • Prefer length over symbols; a long passphrase beats a short scramble.
  • Turn on MFA, preferring an authenticator app or hardware key over text messages.
  • Change a password immediately if you suspect it was exposed.

Do not

  • Reuse a work password anywhere else.
  • Share credentials by email or chat.
  • Approve an MFA prompt you did not trigger.
  • Store passwords in browsers on shared devices or in spreadsheets.

Key takeaways

  • A long, unique passphrase generated and stored by a password manager is generally stronger and more usable than a short password packed with symbols.
  • Multi-factor authentication significantly reduces account takeover risk, and an authenticator app or hardware key resists interception better than text message codes.
  • Approving an MFA prompt that a person did not personally trigger is a common way attackers gain access, so employees should always deny and report unexpected prompts.
  • Reusing a work password on a personal site means a breach of that unrelated site can expose the work account as well.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Template

Password Policy

Modern, usable password and authentication rules that people can actually follow.

Beginner
20 min
Free
NIST SP 800-63
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Employee Security Awareness Checklist

The habits every employee should be able to demonstrate, written as a self-check rather than a lecture.

Beginner
10 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Security Awareness Log

A single record proving who trained, when, on what version, and with what result.

Beginner
15 min
Free
NIST SP 800-171
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Acceptable Use Policy

What employees may and may not do with company systems, data, devices, and AI tools.

Beginner
25 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Access Review Worksheet

A repeatable quarterly review of who has access to what, with a decision recorded for each row.

Intermediate
25 min
Free
NIST SP 800-171
SOC 2

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.